Vulnerability record · CVE-2021-35587 · published 19 January 2022
CVE-2021-35587: Oracle Access Manager OpenSSO Agent missing authentication allows takeover
Oracle · Access Manager
Oracle Access Manager (Fusion Middleware) contains a missing-authentication flaw in the OpenSSO Agent component affecting versions 11.1.2.3.0, 12.2.1.3.0 and 12.2.1.4.0. An unauthenticated network attacker can exploit it over HTTP to fully compromise the product. Because it is remotely reachable without credentials and rated 9.8, it is a high-value target for initial access.
Description
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO Agent). Supported versions that are affected are 11.1.2.3.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 unauthenticated network takeover, KEV-listed with known exploitation, and EPSS above 96 percent make this an urgent patch.
What it is
Oracle Access Manager (Fusion Middleware) contains a missing-authentication flaw in the OpenSSO Agent component affecting versions 11.1.2.3.0, 12.2.1.3.0 and 12.2.1.4.0. An unauthenticated network attacker can exploit it over HTTP to fully compromise the product. Because it is remotely reachable without credentials and rated 9.8, it is a high-value target for initial access.
Impact
Successful exploitation results in complete takeover of Oracle Access Manager, with high confidentiality, integrity and availability impact. An attacker gains control of the affected service and any identity data or sessions it brokers.
Attack surface
Reached over the network via HTTP against the OpenSSO Agent component; no authentication and no user interaction are required per the CVSS vector (AV:N/AC:L/PR:N/UI:N). Any internet- or network-exposed Access Manager instance is in scope.
Exploitation
Listed in CISA KEV since 2022-11-28 with a required remediation date of 2022-12-19, indicating known exploitation in the wild. EPSS is 0.96284 (99.877th percentile), so exploitation is highly likely; no ransomware campaign use is documented.
What to do
- Apply the Oracle January 2022 Critical Patch Update (cpujan2022) for Access Manager 11.1.2.3.0, 12.2.1.3.0 and 12.2.1.4.0.
- If patching cannot be immediate, remove direct network exposure of the OpenSSO Agent/HTTP interface and restrict access to trusted networks.
- Place affected instances behind an authenticating reverse proxy or WAF and block unauthenticated requests to the agent endpoints.
- Rotate credentials and invalidate sessions on any instance that may have been exposed, and review for unauthorized configuration changes.
- Confirm remediation against the CISA KEV due date and track the instance until the patch is verified.
Detection
- Review Access Manager and OpenSSO Agent HTTP logs for unauthenticated requests to agent endpoints, especially anomalous or unexpected paths.
- Hunt for post-exploitation signs: new or modified admin accounts, unexpected configuration changes, and outbound connections from the Access Manager host.
- Monitor for exploitation attempts against exposed Access Manager interfaces using network or WAF signatures and alert on repeated unauthenticated access.
- Correlate host and application logs around the KEV window for indicators of service takeover or session manipulation.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-35587 to the Known Exploited Vulnerabilities catalog on 28 November 2022 as "Oracle Fusion Middleware Unspecified Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 19 December 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.oracle.com/security-alerts/cpujan2022.html | Vendor Advisory |
| https://www.oracle.com/security-alerts/cpujan2022.html | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-35587 | US Government Resource |
Track CVE-2021-35587 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-35587), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.